Whitelisting for programs

Application whitelisting, as available on Windows with, for example, AppLocker or Software Restriction Policies (SRP), does not exist in exactly the same form onLinux® systems. However, there are various approaches to restricting the execution of programs to defined applications, files, services, or integrity states. However, these approaches are less uniform and generally more complex to configure and operate than under Windows.

The reason for this is the increased complexity associated with the command line, scripts, interpreters, and flexible toolchains in Linux® systems, as opposed to the mostly graphical user interface in Windows. Strictly enforced application whitelisting is therefore possible in principle, but in practice it often involves increased maintenance and testing efforts. Particularly with Beckhoff RT Linux® systems, it is also important to note that, depending on their configuration, additional security-related mechanisms can affect runtime behavior, maintainability, and real-time characteristics.

Instead, you should pay close attention to the sources from which packages are obtained and which packages are installed on the system. It is recommended that you use only trusted and verified package sources and install only the software that is actually necessary for the intended operation. Programs, services, interpreters, compilers, and administration tools that are not needed should be removed or not installed in the first place (see Removing components that are no longer needed).

In addition, the execution of unwanted programs can be made more difficult by implementing appropriate system hardening measures. These include, for example, restrictive service configurations, integrity checks, the restriction of writable areas, and appropriate file system options. In practice, however, for Beckhoff RT Linux® systems, a reduced, controlled, and regularly reviewed software inventory is often the most obvious and low-maintenance approach.